Privacy at TapDone
Effective July 24, 2026
TapDone turns spare phones into wall-mounted Done buttons for household tasks. This page explains what data the TapDone apps and this website handle, how we protect it, and the choices you control. "TapDone", "we" and "us" mean the team behind the app; you can always reach us at hello@tapdone.now.
The short version
- Live face recognition stays on your devices. Camera frames are processed briefly in memory and discarded immediately after each match.
- Face enrollment captures are end-to-end encrypted. Your household's devices share them only in sealed form, using a key kept in their secure keychains. Our servers receive encrypted ciphertext only.
- Household data is protected in transit with TLS. Tasks, completions and member names sync through our servers so every Button shows the same up-to-date board.
- Your data is used to operate and improve TapDone. Anonymous usage and diagnostics help us fix bugs. TapDone is ad-free, and your data stays out of the data market.
- You can delete face data — per person or all of it — and your whole household, any time.
1. What we collect, and why
Account
The person who sets up a household signs in with an email address and password. We keep that email and an account identifier, and we email you verification and password-reset codes. Everyone else can join with a pairing code or appear as a name on the board, keeping account details limited to the household organizer.
Household data (synced)
To keep every Button and phone in a household showing the same board, these sync through our servers and are stored there:
- Tasks — names, schedules, points, icons, and who they're assigned to
- Completions — which task was done, when, by which member, how it was credited (face match, picked from a list, guest, or unattributed), and on which Button
- Household members — the first name or nickname you give them, and their role
- Devices — the name you give each Button (like "Hallway") and basic health such as battery level
- Rewards and redemptions, if you use points
We protect this data with TLS whenever it moves between your devices and our servers. TapDone's sync service reads and stores the current household board so it can deliver updates to every device in the household.
Face match (optional)
Face match exists to answer one question — who is standing at the Button — and a household adult controls whether to turn it on. The rest of TapDone works independently of face match.
- Recognition runs on the device. The camera reads frames into memory, computes the match locally, and discards the frames immediately afterward. Live camera content stays on the device.
- Enrollment captures are sealed before they're stored. When you enroll a face, the device encrypts the captures with AES-256-GCM using a key that belongs to your household. The key stays in each device's secure keychain and passes directly from one device to another during pairing.
- Our servers receive encrypted captures. When your household syncs across devices, the captures travel through and rest on our servers as ciphertext that can be opened only by your household's devices.
- Deleting is built in. You can delete any one person's face data, or wipe all face data for the household in one action — both remove the server copies too. Removing a member from the household also deletes their face data.
Task photos
A photo attached to a task remains on the device where it was added, keeping task photos local to that device.
Usage and diagnostics
To build, debug and improve TapDone, we collect anonymous usage and diagnostic data — which features get used, and crash and error reports.
2. Where data lives
TapDone runs on Amazon Web Services in the United States: sign-in accounts, the sync database, and the email service that sends verification codes. AWS processes this data on our instructions solely to provide these services. Your devices also keep a local copy of your household's board.
3. Sharing
Your data serves one purpose: providing TapDone. TapDone is ad-free, and your data stays out of the data market. The cloud services above process it on our instructions to operate the app. If the law requires disclosure, we'll tell you whenever we're legally allowed to do so.
4. Retention and deletion
- Face data — delete per person or household-wide in settings, effective locally and on our servers.
- Members — removing someone deletes their face data; their name remains on past completions unless you delete those too.
- Household and account — email hello@tapdone.now and we'll delete your account and your household's server-side data. Task history otherwise lives for as long as your household does.
5. Children
TapDone is set up and controlled by adults. A child's profile can consist of a first name on the board, while the household organizer manages the account and devices. If an adult enrolls a child's face, recognition stays on-device, enrollment captures sync in end-to-end encrypted form, and the adult can delete them at any time. Child-related information is provided and managed by the household adult.
6. Your choices and rights
You control whether to use face match. We honor requests to access, correct, export or delete your personal data regardless of where you live; email us to make a request.
7. Changes
When this policy changes, we'll update this page and the date at the top. For material changes, we'll explain what is changing on the site before it takes effect.
8. Contact
We're here for privacy questions and deletion requests at hello@tapdone.now.